Signal

New Windows zero-days expose BitLocker bypass and privilege escalation flaws

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-05-13 16:16 UTCUpdated 2026-05-13 16:37 UTC
rss
cveexploitswindowsbitlockerprivilege_escalationsecurity_advisories
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Mystery Microsoft bug leaker keeps the zero-days coming
The Register Security · News · theregister.com · 2026-05-13 16:16 UTC
limited source diversity in top sources
Overview

An anonymous security researcher known as Nightmare-Eclipse has released proof-of-concept exploits for two unpatched Microsoft Windows vulnerabilities called YellowKey and GreenPlasma.

Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
Why now
  • The zero-days were disclosed just after Microsoft's latest Patch Tuesday, highlighting ongoing vulnerabilities.
  • Public release of proof-of-concept code raises the risk of active exploitation.
  • Physical access requirements for YellowKey still pose a significant threat to device security.
Why it matters
  • BitLocker is a key security feature protecting encrypted drives; bypassing it exposes sensitive data.
  • Privilege escalation flaws like GreenPlasma enable attackers to gain full system control.
  • The exploits were released shortly after Microsoft's security updates, increasing risk before patches.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • Nightmare-Eclipse released two Windows zero-days named YellowKey and GreenPlasma.
  • YellowKey is a BitLocker bypass that grants unrestricted shell access with physical access and a USB key sequence.
  • GreenPlasma is a privilege escalation flaw that provides SYSTEM access.
How sources frame it
  • The Register Security: neutral
All evidence
All evidence
Windows BitLocker zero-day gives access to protected drives, PoC released
bleepingcomputer_all · bleepingcomputer.com · 2026-05-13 16:37 UTC
Mystery Microsoft bug leaker keeps the zero-days coming
The Register Security · theregister.com · 2026-05-13 16:16 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • bleepingcomputer_all (1)
  • The Register Security (1)
Top origin domains (this list)
  • bleepingcomputer.com (1)
  • theregister.com (1)